CWE
335 337
Advisory Published
Updated

CVE-2022-40267: Authentication Bypass Vulnerability in Web Server Function on MELSEC Series

First published: Fri Jan 20 2023(Updated: )

Predictable Seed in Pseudo-Random Number Generator (PRNG) vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5U-xMy/z (x=32,64,80, y=T,R, z=ES,DS,ESS,DSS) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 17X**** or later, and versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-xMy/z (x=32,64,96, y=T, z=D,DSS)) with serial number 179**** and prior, and versions 1.074 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MT/DSS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/z (x=24,40,60, y=T,R, z=ES,ESS) versions 1.042 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UJ-xMy/ES-A (x=24,40,60, y=T,R) versions 1.043 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5S-xMy/z (x=30,40,60,80, y=T,R, z=ES,ESS) versions 1.003 and prior, Mitsubishi Electric Corporation MELSEC iQ-F Series FX5UC-32MR/DS-TS versions 1.280 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R00/01/02CPU versions 33 and prior, Mitsubishi Electric Corporation MELSEC iQ-R Series R04/08/16/32/120(EN)CPU versions 66 and prior allows a remote unauthenticated attacker to access the Web server function by guessing the random numbers used for authentication from several used random numbers.

Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp

Affected SoftwareAffected VersionHow to fix
Mitsubishielectric Fx5u-80mt\/ess Firmware
Mitsubishielectric Fx5u-80mt\/ess
Mitsubishielectric Fx5u-32mt\/dss Firmware
Mitsubishielectric Fx5u-32mt\/dss
Mitsubishielectric Fx5u-64mt\/dss Firmware
Mitsubishielectric Fx5u-64mt\/dss
Mitsubishielectric Fx5u-80mt\/dss Firmware
Mitsubishielectric Fx5u-80mt\/dss
Mitsubishielectric Fx5uc-32mt\/d Firmware
Mitsubishielectric Fx5uc-32mt\/d
Mitsubishielectric Fx5uc-64mt\/d Firmware
Mitsubishielectric Fx5uc-64mt\/d
Mitsubishielectric Fx5uc-96mt\/d Firmware
Mitsubishielectric Fx5uc-96mt\/d
Mitsubishielectric Fx5uc-32mt\/dss Firmware
Mitsubishielectric Fx5uc-32mt\/dss
Mitsubishielectric Fx5uc-64mt\/dss Firmware
Mitsubishielectric Fx5uc-64mt\/dss
Mitsubishielectric Fx5uc-96mt\/dss Firmware
Mitsubishielectric Fx5uc-96mt\/dss
Mitsubishielectric Fx5uc-32mt\/ds-ts Firmware<1.280
Mitsubishielectric Fx5uc-32mt\/ds-ts
Mitsubishielectric Fx5uc-32mt\/dss-ts Firmware<1.280
Mitsubishielectric Fx5uc-32mt\/dss-ts
Mitsubishielectric Fx5uc-32mr\/ds-ts Firmware<1.280
Mitsubishielectric Fx5uc-32mr\/ds-ts
Mitsubishielectric R00cpu Firmware
Mitsubishielectric R00cpu
Mitsubishielectric R01cpu Firmware
Mitsubishielectric R01cpu
Mitsubishielectric R02cpu Firmware
Mitsubishielectric R02cpu
Mitsubishielectric R04cpu Firmware
Mitsubishielectric R04cpu
Mitsubishielectric R08cpu Firmware
Mitsubishielectric R08cpu
Mitsubishielectric R16cpu Firmware
Mitsubishielectric R16cpu
Mitsubishielectric R32cpu Firmware
Mitsubishielectric R32cpu
Mitsubishielectric R120cpu Firmware
Mitsubishielectric R120cpu
Mitsubishielectric R04encpu Firmware
Mitsubishielectric R04encpu
Mitsubishielectric R08encpu Firmware
Mitsubishielectric R08encpu
Mitsubishielectric R16encpu Firmware
Mitsubishielectric R16encpu
Mitsubishielectric R32encpu Firmware
Mitsubishielectric R32encpu
Mitsubishielectric R120encpu Firmware
Mitsubishielectric R120encpu
Mitsubishielectric Fx5uj-24mt\/es Firmware<1.042
Mitsubishielectric Fx5uj-24mt\/es
Mitsubishielectric Fx5uj-40mt\/es Firmware<1.042
Mitsubishielectric Fx5uj-40mt\/es
Mitsubishielectric Fx5uj-60mt\/es Firmware<1.042
Mitsubishielectric Fx5uj-60mt\/es
Mitsubishielectric Fx5uj-24mr\/es Firmware<1.042
Mitsubishielectric Fx5uj-24mr\/es
Mitsubishielectric Fx5uj-40mr\/es Firmware<1.042
Mitsubishielectric Fx5uj-40mr\/es
Mitsubishielectric Fx5uj-60mr\/es Firmware<1.042
Mitsubishielectric Fx5uj-60mr\/es
Mitsubishielectric Fx5uj-24mt\/ess Firmware<1.042
Mitsubishielectric Fx5uj-24mt\/ess
Mitsubishielectric Fx5uj-40mt\/ess Firmware<1.042
Mitsubishielectric Fx5uj-40mt\/ess
Mitsubishielectric Fx5uj-60mt\/ess Firmware<1.042
Mitsubishielectric Fx5uj-60mt\/ess
Mitsubishielectric Fx5uj-24mt\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-24mt\/es-a
Mitsubishielectric Fx5uj-40mt\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-40mt\/es-a
Mitsubishielectric Fx5uj-60mt\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-60mt\/es-a
Mitsubishielectric Fx5uj-24mr\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-24mr\/es-a
Mitsubishielectric Fx5uj-40mr\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-40mr\/es-a
Mitsubishielectric Fx5uj-60mr\/es-a Firmware<1.043
Mitsubishielectric Fx5uj-60mr\/es-a
Mitsubishielectric Fx5s-30mt\/es Firmware<1.003
Mitsubishielectric Fx5s-30mt\/es
Mitsubishielectric Fx5s-40mt\/es Firmware<1.003
Mitsubishielectric Fx5s-40mt\/es
Mitsubishielectric Fx5s-60mt\/es Firmware<1.003
Mitsubishielectric Fx5s-60mt\/es
Mitsubishielectric Fx5s-80mt\/es Firmware<1.003
Mitsubishielectric Fx5s-80mt\/es
Mitsubishielectric Fx5s-30mr\/es Firmware<1.003
Mitsubishielectric Fx5s-30mr\/es
Mitsubishielectric Fx5s-40mr\/es Firmware<1.003
Mitsubishielectric Fx5s-40mr\/es
Mitsubishielectric Fx5s-60mr\/es Firmware<1.003
Mitsubishielectric Fx5s-60mr\/es
Mitsubishielectric Fx5s-80mr\/es Firmware<1.003
Mitsubishielectric Fx5s-80mr\/es
Mitsubishielectric Fx5s-30mt\/ess Firmware<1.003
Mitsubishielectric Fx5s-30mt\/ess
Mitsubishielectric Fx5s-40mt\/ess Firmware<1.003
Mitsubishielectric Fx5s-40mt\/ess
Mitsubishielectric Fx5s-60mt\/ess Firmware<1.003
Mitsubishielectric Fx5s-60mt\/ess
Mitsubishielectric Fx5s-80mt\/ess Firmware<1.003
Mitsubishielectric Fx5s-80mt\/ess
Mitsubishi Electric MELSEC iQ-F Series with serial number 17X**** or later:  FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.280 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS<=1.280
Mitsubishi Electric FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS<=1.280
Mitsubishi Electric FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS<=1.280
Mitsubishi Electric MELSEC iQ-F Series with serial number 179**** and prior:  FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS: Versions 1.074 and prior FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS<=1.074
Mitsubishi Electric FX5U-xMy/z x=32,64,80, y=T,R, z=ES,DS,ESS,DSS<=1.074
Mitsubishi Electric FX5UC-xMy/z x=32,64,96 y=T, z=D,DSS<=1.074
Mitsubishi Electric MELSEC iQ-F Series FX5UC-32MT/DS-TS, FX5UC-32MT/DSS-TS, FX5UC-32MR/DS-TS<=1.280
Mitsubishi Electric FX5UJ-xMy/z x=24,40,60, y=T,R, z=ES,ESS<=1.042
Mitsubishi Electric FX5UJ-xMy/ES-A* x=24,40,60, y=T,R<=1.043
Mitsubishi Electric FX5S-xMy/z x=30,40,60,80, y=T,R, z=ES,ESS<=1.003

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the severity of CVE-2022-40267?

    The severity of CVE-2022-40267 is rated as critical with a CVSS score of 9.1.

  • How can I fix the Predictable Seed in Pseudo-Random Number Generator vulnerability in Mitsubishi Electric devices?

    To fix the vulnerability, users should apply the security patches provided by Mitsubishi Electric Corporation for the affected firmware versions.

  • Is my Mitsubishi Electric device vulnerable to CVE-2022-40267?

    Check the list of affected firmware versions provided by Mitsubishi Electric Corporation to determine if your device is vulnerable to CVE-2022-40267.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203